An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway.
The GlobalProtect app on iOS is not affected.
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows.
The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device.
This issue does not apply to the GlobalProtect app on other (non-Windows) platforms.
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM.
GlobalProtect App on Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.
A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.
An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.
End of life: 12/31/2025, End of support: 3/1/2025, Latest version: 6.1.5
End of life: 12/31/2025, End of support: 3/1/2025, Latest version: 6.1.5
End of life: 12/31/2024, End of support: 3/12/2021, Latest version: 5.1.12
End of life: 12/31/2024, End of support: 3/12/2021, Latest version: 5.1.12
End of life: 1/30/2019, End of support: 5/2/2018, Latest version: 4.0
End of life: 1/30/2019, End of support: 5/2/2018, Latest version: 4.0
End of life: 6/23/2018, End of support: 9/23/2017, Latest version: 3.1
End of life: 6/23/2018, End of support: 9/23/2017, Latest version: 3.1
End of life: 2/15/2018, End of support: 5/18/2017, Latest version: 3.0
End of life: 2/15/2018, End of support: 5/18/2017, Latest version: 3.0
Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.